Threadlinqs IntelligenceStart free

ATT&CK techniqueExecutionPersistencePrivilege Escalation

T1053 Scheduled Task/Job

ExecutionPersistencePrivilege EscalationEnterprise

As of 2026-10-05, T1053 (Scheduled Task/Job) appears in 271 tracked threats, first reported 2021-11-25 and most recently 2026-09-27, with linked actors including APT28, Forest Blizzard, APT38; it most often appears alongside T1059 (Command and Scripting Interpreter).

Tracked threats
27194 critical, 162 high, 12 medium, 2 low
First seen
2021-11-25
Last seen
2026-09-27
Threat actors
102In the threats using it
Detection rules
56Blue tier and above

Data as of:

Activity timeline

T1053 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 77 reports, and 270 of the 271 threats were reported in the twelve months to 2026-09.

How adversaries use it

T1053 Scheduled Task/Job is catalogued by MITRE ATT&CK under the Execution and Persistence and Privilege Escalation tactics in the Enterprise matrix. Threadlinqs maps 271 of 2623 tracked threats (10.3%) to it; by severity that is 94 critical, 162 high, 12 medium, 2 low.

Threats that use T1053 most often also use T1059 Command and Scripting Interpreter (234 threats), T1071 Application Layer Protocol (211 threats), T1027 Obfuscated Files or Information (203 threats), T1036 Masquerading (193 threats), T1082 System Information Discovery (187 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

102 tracked threat actors appear in the threats that use T1053; the most frequent are APT28 (8), Forest Blizzard (7), APT38 (6), BlueDelta (6), TeamPCP (6).

Mitigations

MITRE ATT&CK lists 5 mitigations for T1053.

Data sources

Telemetry that can reveal T1053, per MITRE ATT&CK.

  • Command — Command Execution
  • Container — Container Creation
  • File — File Creation, File Modification
  • Process — Process Creation
  • Scheduled Job — Scheduled Job Creation

Threat actors using it

Tracked threats

The 30 most recent of 271 tracked threats that use T1053.

Detection coverage

Threadlinqs maintains 56 detection rules mapped to T1053 (SPL 20, KQL 18, Sigma 18). Rule content is available to Blue tier accounts and above; this page shows counts only.

56 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Sub-techniques

  • T1053.001 At (Linux) — 0 tracked threats
  • T1053.002 At — 1 tracked threat
  • T1053.003 Cron — 61 tracked threats
  • T1053.004 Launchd — 1 tracked threat
  • T1053.005 Scheduled Task — 216 tracked threats
  • T1053.006 Systemd Timers — 3 tracked threats
  • T1053.007 Container Orchestration Job — 0 tracked threats